← Back
MalwareSecurity Affairs·5 hours ago

ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool

ValleyRAT leverages legitimate-looking adware and DLL sideloading techniques to evade detection while enabling the Silver Fox threat actor to steal data and maintain control over compromised systems. By disguising itself within seemingly ordinary applications rather than relying solely on cracked software or fake updates, the malware demonstrates an evolving approach to persistence and evasion on infected machines.

Read full article at Security Affairs

Related Articles

MalwareThe Hacker News·12 hours ago

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

Silver Fox threat actors are distributing the ValleyRAT backdoor disguised as QN Wallpaper, a legitimate Chinese desktop-wallpaper application, which users often add to antivirus exclusions due to its signed status. By running the malware under this trusted process, attackers can evade detection on systems where users have already whitelisted the application. Kaspersky identified this distribution method as part of the group's campaign to establish backdoor access while bypassing security controls.

MalwareDark Reading·3 hours ago

Anthropic Users Hit by Infostealer Attacks, Session Thefts

A threat actor leveraged multiple infostealer malware variants to harvest session credentials and gain unauthorized access to Claude accounts across an unspecified number of Anthropic users. The campaign demonstrates the ongoing risk that infostealers pose to SaaS platform users, particularly when session tokens are compromised and can be weaponized for account takeover.